/** * HTTP entrypoint — the hosted form of the TracePass MCP server. * * Runs as a standalone Node service (deployed to Hetzner, served at * https://ai.tracepass.eu/mcp). An MCP client connects over * Streamable HTTP; the caller's TracePass credential travels in the * `Authorization: Bearer ` header of every request. * * BOTH v1 auth methods work here, transparently — we forward the * Bearer token to the v1 API unchanged and the platform's unified gate * decides: a `tp_…` API key (service account) OR an OAuth 2.0 access * token (user-authorized, scoped). The server neither parses nor cares * which; it's a pass-through. OAuth-capable MCP clients (Claude.ai, * ChatGPT) discover the flow via the 401 `resource_metadata` param and * the server card; simpler clients paste a tp_ key. * * Stateless by design: each MCP request is self-contained, so we * build a fresh server + transport per request, bound to that * request's token. No server-side session state — which means the * service scales horizontally and a restart drops nothing. * * This is the SAME server core (`createMcpServer`) the stdio * entrypoint uses — only the transport + the key source differ. * * Env: * PORT (optional) — listen port, default 8080 * TRACEPASS_BASE_URL (optional) — the TracePass API base URL the * tools call, default https://app.tracepass.eu. In prod * this is the INTERNAL Docker address (platform:3000). * TRACEPASS_AUTH_SERVER_URL (optional) — the PUBLIC authorization-server * origin advertised in OAuth discovery metadata, default * https://app.tracepass.eu. Set this when BASE_URL is an * internal address so clients get a reachable auth server. */ export {}; //# sourceMappingURL=http.d.ts.map